Effective Date: 4 August 2026 · Last Updated: 5 August 2026
Exerevno Limited ("Exerevno", "we", "us", or "our") operates Sartia, a personal color analysis app for iOS and Android (the "App" or the "Service"). Sartia is built by Exer-labs, the product studio of Exerevno Limited.
This Privacy Policy explains what personal information the App collects, how we use and protect it, how long we keep it, and the rights you have in respect of it. It should be read alongside our Terms of Use.
The short version. Sartia analyses a photo of your face to work out your color season. Your photo is used only to create your result and is deleted within 24 hours (immediately after a successful analysis in normal operation), unless you turn on the optional retention setting. We never use your photo or your results to train AI models, and we never sell or share your personal information for advertising. We keep your color results, not your photo.
By using the App you acknowledge that you have read and understood this Privacy Policy. The analysis of your photo happens only after you give explicit, separate consent on the consent screen shown before your first analysis.
Exerevno Limited acts as the data controller for personal information processed through Sartia. Our contact details are in Section 13.
| What | Why we collect it | How long we keep it |
|---|---|---|
| Your face photo | To produce your personal color result. This is the only image we ever handle. | Deleted within 24 hours by default, and immediately after a successful analysis in normal operation. Kept only if you turn on the optional retention setting, until you delete it or delete your account. |
| Onboarding quiz answers (style goal, color frustration, warm or cool confidence, self-reported natural hair and eye color, occasions, shopping frequency, age range) | To personalise your analysis and guidance. Your self-reported hair and eye color feed the analysis. | While your account is active. If you never create an account by purchasing, these are purged automatically 30 days after collection. |
| Email address captured at the end of the quiz, before any purchase | To deliver your color profile and, only with your consent, to send you offers. | Same as quiz answers: 30 days if you do not create an account, otherwise while your account is active. |
| Account email and sign-in identifiers (including your Google or Apple sign-in subject and session tokens) | To create and secure your account and log you in. | While your account is active. |
| Derived color measurements and your season result (skin, eye, and hair color values, undertone, contrast level, season, confidence) | These are your saved report. They are non-image values and cannot be used to reconstruct your face. | While your account is active. |
| Facial structure descriptors (Style+ subscribers only) | To tailor style guidance to your features. We store qualitative descriptors only, never landmark coordinates or any template that could re-identify you. | While your account is active. |
| Purchase and subscription records (amount, currency, status, store and RevenueCat identifiers, entitlement state) | To unlock what you have paid for and to keep our financial records. | While your account is active, and afterwards only where tax and accounting law requires, in minimal form. |
| An anonymous token generated by our server and stored on your device | To tie your quiz, photo, and result together before you have an account. It is a random token, not a device fingerprint and not an advertising identifier. | Until it is migrated to your account, or purged with the anonymous data at 30 days. |
| Operational and error logs | To keep the Service working and diagnose faults. | A short rolling window. Logs never contain your photo or any reversible biometric data. |
For users in the EEA, UK, or Switzerland, we rely on the following legal bases:
| Processing Activity | Legal Basis |
|---|---|
| Processing your face photo and deriving your color and facial structure results | Explicit consent (Article 6(1)(a) and Article 9(2)(a)), given on the consent screen shown before your first analysis. No photo is captured or uploaded before you accept. |
| Collecting your email at the end of the quiz and sending you your color profile | Consent (Article 6(1)(a)) given at the email capture screen, with the purpose stated on that screen. |
| Marketing email | Consent (Article 6(1)(a)), recorded separately. Every message includes an unsubscribe link. |
| Creating and running your account, and delivering what you purchased | Contract (Article 6(1)(b)). |
| Keeping financial and tax records | Legal obligation (Article 6(1)(c)). |
| Securing the Service, rate limiting, and diagnosing faults | Legitimate interests (Article 6(1)(f)): keeping the Service available, safe, and free from abuse. |
Consent is granular and never pre-ticked. You can withdraw it at any time: turn photo retention off to delete a retained photo, unsubscribe from marketing email, or delete your account entirely (see Section 9 and our account deletion page). Withdrawing consent is as easy as giving it. If the consent text materially changes, we ask you to consent again before your next analysis.
This is the part people most want to understand, so here it is in full:
The only literal image we handle is transient. Everything we retain is a derived measurement that cannot reconstruct your face.
We share information only with the service providers listed below, each acting as a processor on our instructions, and where required by law.
| Provider | Purpose | Privacy Policy |
|---|---|---|
| Supabase | Hosting, database, private photo storage, authentication, and the server-side functions that run the analysis | supabase.com/privacy |
| Google LLC (Gemini API, paid tier) | The vision model that analyses your photo to produce your result. Paid-tier content is not used to train Google's models. | policies.google.com/privacy |
| RevenueCat, Inc. | Subscription status and store receipt validation. No card data. | revenuecat.com/privacy |
| Apple (App Store) and Google (Google Play) | Payment processing, subscription billing, and app distribution. Your payment details are given to the store, never to us. | apple.com/legal/privacy · policies.google.com/privacy |
We may also disclose information if required by law, court order, or a governmental authority, or where we believe in good faith that disclosure is necessary to protect the rights, property, or safety of Exerevno Limited, our users, or the public. In the event of a merger, acquisition, or sale of all or substantially all of our assets, your information may be transferred to the successor entity, and we will notify you of any new privacy policy that applies.
We honour the strongest applicable standard across all our markets rather than running different flows per country.
We verify rights requests through your own signed-in session so that we act only on the account holder's request. We respond without undue delay and within one month, the strictest window that applies to us, extendable by two further months for complex requests under Article 12(3) GDPR.
You may also complain to your local supervisory authority: in the EEA see edpb.europa.eu, in the UK the Information Commissioner's Office (ico.org.uk), in New Zealand the Office of the Privacy Commissioner (privacy.org.nz), and in Australia the Office of the Australian Information Commissioner (oaic.gov.au).
Our processors operate outside some users' countries of residence, including in the United States. By using the App you acknowledge that your information may be transferred to and processed in jurisdictions with different data-protection laws than your own.
Transfers from the EEA, UK, or Switzerland: where personal data is transferred to a country without an adequacy decision, we rely on each provider's appropriate safeguards, including the European Commission's Standard Contractual Clauses (2021/914) and the UK International Data Transfer Addendum, as published by that provider.
Transfers from New Zealand: we comply with Information Privacy Principle 12 of the NZ Privacy Act, including by selecting providers whose terms ensure comparable safeguards.
Sartia is for users aged 16 and over and is not directed to children under 16. You confirm your age when you accept the analysis consent screen. If we learn that we hold information from someone under 16, we delete it. If you believe a person under 16 has used the App, contact us at hyon.shim@exerevno.co.nz.
Sartia is for analysing your own appearance. Do not upload a photo of another person unless that person has agreed to be analysed. You are responsible for having that person's consent.
No method of electronic transmission or storage is completely secure. While we strive to protect your information, we cannot guarantee absolute security. If a notifiable breach occurs we follow the applicable rules in each jurisdiction, including the NZ Privacy Act 2020 notifiable privacy breach scheme, the Australian Notifiable Data Breaches scheme, and the GDPR's 72-hour supervisory authority notification requirement.
For any question, concern, or request relating to this Privacy Policy or your personal information, please contact us:
Exerevno Limited
13/30 Upper Queen St, Auckland 1010, New Zealand
Email: hyon.shim@exerevno.co.nz
Website: www.exerevno.co.nz
We may update this Privacy Policy from time to time. When we do, we will revise the "Last Updated" date above and, where changes are material, take reasonable steps to notify you in the App. Where a change materially affects the consent you gave for photo analysis, we will ask you to consent again before your next analysis.